Information disclosure in OpenSSL - CVE-2017-3732
Published: January 27, 2017 / Updated: January 27, 2017
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to propagating error in the x86_64 Montgomery squaring procedure. A remote attacker with access to unpatched vulnerable system that uses a shared private key with Diffie-Hellman (DH) parameters set can gain unauthorized access to sensitive private key information.
According to vendor’s advisory, this vulnerability is unlikely to be exploited in real-world attacks, as it requires significant resources and online access to an unpatched system using the target private key in a scenario with persistent DH parameters and a private key that is shared between multiple clients.
Vulnerability exploitation against RSA and DSA as a result of this defect would be very difficult to perform and are not believed likely.
Affected software
Gentoo Linux
Amazon Linux AMI
Arch Linux
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for Power, little endian
FreeBSD
SUSE Linux
Ubuntu
Slackware Linux
Fedora
Opensuse
openssl (Alpine package)
Data ONTAP operating in 7-Mode
openssl
java-1.8.0-ibm-plugin (Red Hat package)
java-1.8.0-ibm (Red Hat package)
java-1.8.0-ibm-demo (Red Hat package)
java-1.8.0-ibm-devel (Red Hat package)
java-1.8.0-ibm-jdbc (Red Hat package)
java-1.8.0-ibm-src (Red Hat package)
Planning Analytics Local
IBM Cognos Analytics
IBM Algo One Core
IBM Cognos Controller
MySQL Server
Red Hat Satellite
IBM MQ
NetWorker
IBM Cloud Pak for Business Automation
SnapDrive for Windows
Tivoli Network Manager IP Edition
How to mitigate CVE-2017-3732
SnapDrive for Windows - update to 7.1.4P1
Data ONTAP operating in 7-Mode - update to 8.2.5
IBM Cognos Analytics - update to 11.0.13
openssl - addressed in versions 1.0.2k-1.fc24, 1.0.2k-1.fc25
java-1.8.0-ibm-plugin (Red Hat package) - addressed in versions 1.8.0.5.20-1jpp.1.el6_10, 1.8.0.5.20-1jpp.1.el7
java-1.8.0-ibm (Red Hat package) - addressed in versions 1.8.0.5.20-1jpp.1.el6_10, 1.8.0.5.20-1jpp.1.el7
java-1.8.0-ibm-demo (Red Hat package) - addressed in versions 1.8.0.5.20-1jpp.1.el6_10, 1.8.0.5.20-1jpp.1.el7
java-1.8.0-ibm-devel (Red Hat package) - addressed in versions 1.8.0.5.20-1jpp.1.el6_10, 1.8.0.5.20-1jpp.1.el7
java-1.8.0-ibm-jdbc (Red Hat package) - addressed in versions 1.8.0.5.20-1jpp.1.el6_10, 1.8.0.5.20-1jpp.1.el7
java-1.8.0-ibm-src (Red Hat package) - addressed in versions 1.8.0.5.20-1jpp.1.el6_10, 1.8.0.5.20-1jpp.1.el7
Tivoli Network Manager IP Edition - addressed in versions 3.9.0.132, 4.1.1.49, 4.2.0.5
NetWorker - update to 19.10.0.0
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3-IF037, 24.0.0-IF003
External References
Related Security Bulletins
- Multiple vulnerabilities in OpenSSL
- FreeBSD update for OpenSSL
- Gentoo update for OpenSSL
- Ubuntu update for OpenSSL
- Slackware Linux update for openssl
- Multiple vulnerabilities in Oracle MySQL Server
- openSUSE update for openssl-steam
- Gentoo update for MySQL
- Multiple vulnerabilities in IBM Cognos Controller
- Arch Linux update for lib32-openssl
- Arch Linux update for openssl
- Amazon Linux AMI update for openssl
- OpenSUSE Linux update for openssl
- SUSE Linux update for openssl
- Multiple vulnerabilities in IBM MQ
- Multiple vulnerabilities in IBM Algo One Core
- Multiple vulnerabilities in IBM Planning Analytics Local
- Multiple vulnerabilities in IBM Cognos Analytics
- Information disclosure in openssl (Alpine package)
- Multiple vulnerabilities in N series Products
- Multiple vulnerabilities in IBM Tivoli Network Manager IP Edition
- Multiple vulnerabilities in Dell Networker
- Fedora 25 update for openssl
- Fedora 24 update for openssl
- Red Hat Enterprise Linux 7 Supplementary update for java-1.8.0-ibm
- Red Hat Enterprise Linux 6 Supplementary update for java-1.8.0-ibm
- Red Hat Satellite 5 update for java-1.8.0-ibm
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation